Jérôme Segura

Security Researcher focusing on web threats

2025-10-14

PSA: A malicious download for Comet browser by Perplexity is currently being advertised via Google Ads.

At DataDome we are seeing more and more traffic coming from AI agents and browsers. Criminals are taking notice and buying ads related to Agentic browsers (another malicious campaign for Arc browser is also running).

Malicious ad ➡️ cometswift[.]com ➡️ perplexity[.]page ➡️ GitHub

Payload: hxxps[://]github[.]com/richardsuperman/musical-engine/releases/download/beta/comet_latest[.]msi
Command and Control (C2) server: icantseeyou[.]icu
VirusTotal: virustotal.com/gui/file/64562a

#malvertising #cometbrowser

2024-09-23

#malvertising Obsidian

2024-09-19

@Lee_Holmes @briankrebs for better or worse PowerShell has become somewhat associated with malicious activity (for those in the security space looking at malware).

Remote desktop applications have also inherited a bad reputation as scammers often use them.

But you are absolutely correct, getting the user to do anything at this point is the issue.

2024-09-16

Credit card 'img' skimmer domain:

trendgurupro[.]com

Part of this campaign: malwarebytes.com/blog/news/202

2024-09-11

@Ericlaw is Internet Explorer still being used or is that the default title header?

2024-09-11

Malicious Google Ads for Apple suport

hxxps[://]applescustomerservice24x7care1102[.]vercel[.]app/

hxxps[://]apples24x7-customersupporthelp[.]github[.]io/saf/

2024-09-10

Malicious Google Ad for WinSCP

winscp[.]corysound[.]com
winscpp[.]net
badlink58[.]com/wp-includes/fonts/WinSCP-6.3.4.zip

A Google search for WinSCP; the top ad is maliciousNetwork traffic using mitmproxy
2024-09-09

Malicious Google ad for Microsoft Support

hxxps[://]microsft-customer-helpline[.]vercel[.]app

A malicious Google ad for Microsoft support
2024-09-05
A malicious Google ads leads to a phishing site for Lowe's employee portal.
2024-08-30

Malicious Google Ad for Cisco AnyConnect

cisco[.]com[.]gruaselpiojito[.]com[.]mx

cisco[.]com[.]gruaselpiojito[.]com[.]mx/download/cisco-secure-client-win-5[.]0[.]05040-core-vpn-predeploy-k9[.]exe

NetSupport RAT, C2: sivacycle[.]com

virustotal.com/gui/file/c43272

2024-08-28

@Lee_Holmes Not really, but I just started digging into this more recently so I suspect there are many variations of it.

Come to think of it, it's just a form of spam, looking for any way they can inject data into legitimate/official sources.

2024-08-27

Malicious Google ad for Zoom

pacificfisherman[.]com
zoomi[.]company
zoomi[.]company/Zoom[.]exe

virustotal.com/gui/file/21b075

2024-08-26

SocGholish/FakeUpdates

jswebcloud[.]com
premium[.]davidabostic[.]com

C2: contest[.]printondemandmerchandise[.]com

2024-08-26

@Lee_Holmes thanks, I'm glad it's not just disabling one URL at a time, but an entire account.

Here's the larger campaign I was talking about. Not sure what MSFT can do about it, but it's a real issue: malwarebytes.com/blog/scams/20

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst